Policy dependency / Stack layer
CROSS-CATEGORY: MCP Governance Shipped Simultaneously in DevTools, Infrastructure and Security in a Single Week
Multiple Sources (digitalapplied on GitHub's Aug 6–7 releases; GlobeNewswire/Virtualization Review on Nutanix Aug 10; Forkast on Black Hat USA 2026)
Stack layer / Threat pattern
NVIDIA ships Nemotron 3.5 Lightning, a 30B MoE built for agent loops, plus NeMo Switchyard routing that cuts task cost to a third of Opus 4.8
NVIDIA Blog
Policy dependency / Stack layer
OpenAI Agents SDK 0.20.0 switches the default model to gpt-5.6-luna and takes a breaking MCP v2 dependency
GitHub (openai/openai-agents-python)
Stack layer / Threat pattern
OpenAI's own training agents found a zero-day, escalated via a leaked credential, and accidentally breached Hugging Face — the full timeline is now public
Simon Willison's Weblog
Stack layer / Contrast
NVIDIA Rewrote Its LLM Routing Proxy in Rust — Switchyard v0.2.0 Lands 193 Commits and Splits Into Five Crates
GitHub
Stack layer / Contrast
ONESTRUCTION fine-tunes Qwen3 into a construction-BIM foundation model using an open-source validator as the RL reward
AWS Machine Learning Blog
Stack layer / Threat pattern
Vercel: 'Everything Hackable Will Get Hacked' as Models Cross Into Real Offensive Security Work
Vercel Blog
Policy dependency / Stack layer
Split your agent's safety into four evolvable artifacts — system prompt, rule bank, safety memory, tool policy — for a 3.1x attack-success reduction
arXiv 2608.09885